Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Crypto ISAKMP Policy?

Here is a newbie question. I have a remote 5520 ASA that is configured with a l2l tunnel. The remote ASA has two Crypto ISAKMP policies. How can I tell which policy the ASA is using for the l2l tunnel? The main ASA also has both policies. I just want to clean up the policy that is not being used. Thanks for any help!

Dave

2 REPLIES

Crypto ISAKMP Policy?

The process is something like this-

during phase 1 the initiator sends all of their configured isakmp policies to the peer.The responder then compares its number one policy to all of the policies sent by the peer, stopping as soon as there is a match.If there is no match, then the responder compares its number two policy to all of the policies sent by the peer, stopping as soon as there is a match.This process repeats until a match is found, if no match is found then no SA forms.

You can have multiple policies configured just see both end are configured for same policy .The extra one you can delete.

Thanks

Ajay

New Member

Crypto ISAKMP Policy?

Ajay,

     Thanks for the info.  That is what I am looking for. 

     Dave

405
Views
5
Helpful
2
Replies
CreatePlease login to create content